CVE-2021-25275
- EPSS 0.11%
- Veröffentlicht 03.02.2021 17:15:16
- Zuletzt bearbeitet 21.11.2024 05:54:39
SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and uses a SQL Server backend, and stores database credentials to access this backend in a file readable by unprivileged users. As a result, any user having a...
- EPSS 50.23%
- Veröffentlicht 03.02.2021 17:15:16
- Zuletzt bearbeitet 21.11.2024 05:54:39
The Collector Service in SolarWinds Orion Platform before 2020.2.4 uses MSMQ (Microsoft Message Queue) and doesn't set permissions on its private queues. As a result, remote unauthenticated clients can send messages to TCP port 1801 that the Collecto...
CVE-2020-10148
- EPSS 94.3%
- Veröffentlicht 29.12.2020 22:15:12
- Zuletzt bearbeitet 24.10.2025 14:36:09
The SolarWinds Orion API is vulnerable to an authentication bypass that could allow a remote attacker to execute API commands. This vulnerability could allow a remote attacker to bypass authentication and execute API commands which may result in a co...
- EPSS 1.53%
- Veröffentlicht 17.09.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 05:00:47
Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).
CVE-2019-12864
- EPSS 0.22%
- Veröffentlicht 04.05.2020 14:15:12
- Zuletzt bearbeitet 21.11.2024 04:23:43
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) is vulnerable to Information Leakage, because of improper error handling with stack traces, as demonstrated by discovering a full pathname upon a 500 Internal Server Error via the api2/sw...
CVE-2019-12863
- EPSS 1.86%
- Veröffentlicht 25.02.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:23:43
SolarWinds Orion Platform 2018.4 HF3 (NPM 12.4, NetPath 1.1.4) allows Stored HTML Injection by administrators via the Web Console Settings screen.
CVE-2019-17127
- EPSS 2.26%
- Veröffentlicht 17.01.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 04:31:44
A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This ...
CVE-2019-17125
- EPSS 2.83%
- Veröffentlicht 17.01.2020 18:15:13
- Zuletzt bearbeitet 21.11.2024 04:31:44
A Reflected Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS.
CVE-2019-9546
- EPSS 1.73%
- Veröffentlicht 01.03.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:51:49
SolarWinds Orion Platform before 2018.4 Hotfix 2 allows privilege escalation through the RabbitMQ service.